SV-224867r569186_rule
V-224867
SRG-OS-000021-GPOS-00005
WN16-AC-000020
CAT II
10
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy >> "Account lockout threshold" to "3" or fewer invalid logon attempts (excluding "0", which is unacceptable).
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy.
If the "Account lockout threshold" is "0" or more than "3" attempts, this is a finding.
For server core installations, run the following command:
Secedit /Export /Areas SecurityPolicy /CFG C:\Path\FileName.Txt
If "LockoutBadCount" equals "0" or is greater than "3" in the file, this is a finding.
V-224867
False
WN16-AC-000020
Verify the effective setting in Local Group Policy Editor.
Run "gpedit.msc".
Navigate to Local Computer Policy >> Computer Configuration >> Windows Settings >> Security Settings >> Account Policies >> Account Lockout Policy.
If the "Account lockout threshold" is "0" or more than "3" attempts, this is a finding.
For server core installations, run the following command:
Secedit /Export /Areas SecurityPolicy /CFG C:\Path\FileName.Txt
If "LockoutBadCount" equals "0" or is greater than "3" in the file, this is a finding.
M
4205